Malicious PDF — malware analysis report

Static analysis result for SHA-256 93cd16feaeda6e00…

MALICIOUS

PDF

342.0 KB Created: 2022-01-18 16:54:58 Authoring application: Smallpdf Desktop First seen: 2026-05-13
MD5: 5dba9ee5e57c06b143b15bd34d656872 SHA-1: 81127011f65229678550477082ca5cedad84f1d1 SHA-256: 93cd16feaeda6e0049d8794496f6c1355fa967bc40c562e5e24a8375519d0b08
134 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0216

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINK
    PDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cafij.co.za/XSRYdR1H?utm_term=everybody+hates+chris+free+online+season+1 PDF link annotation
    • http://akbmodel.com/wp-content/plugins/formcraft/file-upload/server/content/files/161f8bc8ec40a7---lireputanakurebinetu.pdfIn PDF document text
    • http://mawratanews.com/armedia/uploads/files/97484763387.pdfIn PDF document text
    • http://ylplj.com/ckfinder/userfiles/files/dilepafavadolaxoxune.pdfIn PDF document text
    • http://ridonhennet.eu/admin/kcfinder/upload/files/28725987661.pdfIn PDF document text
    • http://cambridgekapurthala.com/damana/userfiles/file/jorobe.pdfIn PDF document text
    • http://thibangoto.com/app/webroot/uploads/files/jeteramepejamokulumine.pdfIn PDF document text
    • http://dryoucosmeceutical.com/userfiles/files/wasofufanudujuxuzidugoda.pdfIn PDF document text
    • http://iq-money.ru/upload/files/zepunijunagi.pdfIn PDF document text
    • http://ustunongel.com/image/files/zudoseg.pdfIn PDF document text
    • https://www.lashharmony.co.uk/wp-content/plugins/super-forms/uploads/php/files/tqmitufvep990huk4gifbhh0t6/39045705951.pdfIn PDF document text
    • http://halvani.com/wp-content/plugins/formcraft/file-upload/server/content/files/1623449c91ce28---bojigepajovenixumebi.pdfIn PDF document text
    • http://mondoacquapiscine.com/userfiles/files/51290500371.pdfIn PDF document text
    • http://rana-international.com/userfiles/files/43679181502.pdfIn PDF document text
    • https://houstoncoinshow.org/FCKeditor/file/40657463908.pdfIn PDF document text
    • http://daoltrading.com/userData/board/file/fetuvedusuzizeloponizix.pdfIn PDF document text
    • http://www.rlktechniek.nl/wp-content/plugins/formcraft/file-upload/server/content/files/16203b7415d0e1---22150860158.pdfIn PDF document text
    • http://topimmigrationlawyer.org/ckfinder/userfiles/files/vuwaloloba.pdfIn PDF document text
    • http://bona-concretebatchplant.com/d/files/nuzajefexusog.pdfIn PDF document text
    • https://agsposure.org/wp-content/plugins/super-forms/uploads/php/files/d8d66925a9baa2225d2284f84693136a/vasevotobebatixowaze.pdfIn PDF document text
    • http://studiorinaldibedin.eu/userfiles/files/31605624592.pdfIn PDF document text
    • http://cpgny.com/userfiles/files/memoradanepunawasixovume.pdfIn PDF document text
    • https://dla-pracownika.pl/pliki_user/File/33749115239.pdfIn PDF document text
    • http://automag.pl/userfiles/file/galalugemuwedawid.pdfIn PDF document text
    • http://www.siscard.com/wp-content/plugins/formcraft/file-upload/server/content/files/1621fdce6b9798---vabitaloxarujavumosu.pdfIn PDF document text
    • http://casier-a-bouteilles.com/file/94611279010.pdfIn PDF document text
    • https://www.coconutlodge.com/wp-content/plugins/formcraft/file-upload/server/content/files/1622458d7af8b2---vubewukepunufefi.pdfIn PDF document text
    • https://neipco.ir/data/file/27661615625.pdfIn PDF document text
    • https://www.hagensmarketing.com/wp-content/plugins/formcraft/file-upload/server/content/files/16227a598c83f9---76467891657.pdfIn PDF document text
    • http://www.bombillasconled.com/archivos/files/86262693233.pdfIn PDF document text
    • https://ssekolkata.com/ckfinder/userfiles/files/kobidudorusezutona.pdfIn PDF document text
    • http://sanraimundo.cl/dyn/uploads/file/43716552651.pdfIn PDF document text
    • http://ingatlantv.tv/userfiles/files/94836633333.pdfIn PDF document text
    • https://topconta.ro/userfiles/file/2246598634.pdfIn PDF document text
    • http://microsolder.hu/userfiles/files/29392609659.pdfIn PDF document text
    • https://www.massola.com/assets/themes/sbadmin2/ckeditor/kcfinder/upload/files/vubun.pdfIn PDF document text
    • https://tiger-security.net/webroot/upload/files/7673140968.pdfIn PDF document text
    • http://attilacenter.org/userfiles/file/10242197776.pdfIn PDF document text
    • https://istanajp.net/contents/files/pezatexogunugovezakerib.pdfIn PDF document text
    • http://brothersconsultingllc.com/kcfinder/upload/files/dapexagakixavu.pdfIn PDF document text
    • https://travelselection.us/wp-content/plugins/formcraft/file-upload/server/content/files/1623297018859b---xabobukugetip.pdfIn PDF document text
    • http://nikkenj.com/userfiles/file/35714444224.pdfIn PDF document text
    • https://full-flavors.com/img/Data/file/mujelotamaderibajage.pdfIn PDF document text
    • https://maytuixachanquynh.kimtuong.vn/isc/public/files/fckupload/file/rumeze.pdfIn PDF document text
    • http://srividyaastrology.com/userfiles/file/nufunubezivukevarot.pdfIn PDF document text
    • http://ghefoot.com/fckeditor_userfiles/file/50891529948.pdfIn PDF document text
    • http://www.recetasyconsejos.com/wp-content/plugins/formcraft/file-upload/server/content/files/1620eef1817cee---tuzedewifekofejer.pdfIn PDF document text
    • https://t.me/pdfmag24In PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    +6 more URL(s)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0004eb22.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4EB22 16560 bytes
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9
font_01_sfnt_off0005013f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5013F 10928 bytes
SHA-256: a7e3101b1738bce72fd2cc7145df092f984e7ddfe4dceded4fbbd7883fb1da91
font_02_sfnt_off000519e9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x519E9 18400 bytes
SHA-256: 78483d75bcd07f2e6eb7c133c50c365fe6877ed4da73336aaeda830df24e058f